The SECO/WARWICK Group, the parent company of SECO/VACUUM Technologiesand SECO/WARWICK USA, has announced plans to bolster its production capacity in the U.S., increasing its footprint and workforce. The expansion will include relocating a portion of its manufacturing and a metallurgical lab for vacuum furnaces from its headquarters site in Poland to Crawford County, Pennsylvania.
The 120,000-sq ft facility located in Meadville, PA, will house equipment for furnace production and serve the company’s North American customers through the addition of parts, service, and training capacity, resulting in an increase in its heat treat manufacturing workforce. an international furnace manufacturer
SECO/WARWICK Group announced that this expansion received support from the Commonwealth of Pennsylvania through a $2 million package of matching fund grants from the Department of Community and Economic Development (DCED) through its Redevelopment Assistance Capital Program (RACP). The primary use and intent of RACP funds is for reimbursement of eligible construction costs which SECO/WARWICK Group companies will match on a 1:1 basis. The Commonwealth will also provide an additional $69 thousand in matching funds for job training through the Workforce & Economic Development Network (WEDnet).
Employees of SECO/VACUUM Technologies and SECO/WARWICK at the announcement of the Meadville, PA, site expansion, held jointly by The SECO/WARWICK Group and the Commonwealth of PA Department of Community and Economic Development Source: Heat Treat Today
State, county and local officials as well as representatives from the international and US-based offices of the SECO/WARWICK Group were present at an event marking the expansion.
“Governor Shapiro is committed to making Pennsylvania an economic leader by investing in the growth of businesses like SECO/VACUUM and SECO/WARWICK,” stated the Commonwealth in the grant award letter. “In addition to the financing package outlined above, the Governor’s Action Team is prepared to provide both companies with any assistance that may be required throughout the application process, as well as to coordinate the involvement of all other state agencies in the project.”
“We look forward to working with our local partners including the City of Meadville, the Economic Progress Alliance of Crawford County (EPACC), the Workforce and Economic Development Network (WEDnet), and the Pennsylvania Department of Community and Economic Development (DCED) to make this expansion happen!” said Piotr Zawistowski, president and managing director of SECO/VACUUM.
Pictured in feature image (L to R): Don Marteeny, vice president of engineering; Slawomir Wozniak, president and CEO, SECO/WARWICK Group; Piotr Zawistowski, president and managing director of SECO VACUUM Technologies
The press release is available in its original form here.
At the front of some major developments in heat treat technologies is Slawomir Wozniak, CEO of SECO/WARWICK. Join him and Heat TreatRadiohost and Heat Treat Today publisher, Doug Glenn, as he talks about the latest trends in heat treat, especially the new technologies his company is pursuing and the effect of the War in Ukraine. Read a recent press release with information about the group here.
Below, you can watch the video, listen to the podcast by clicking on the audio play button, or read an edited transcript.
The following transcript has been edited for your reading enjoyment.
Doug Glenn: The last time we spoke in an interview was in 2019. We were in Germany at Thermprocess, and you were just getting into the CEO position. We’re coming up on 4 years. How has it been? For you personally and for the company?
Sławomir Woźniak CEO SECO/WARWICK Source: secowarwick.com
Slawomir Wozniak: A good question. Yes, it was a very nice time.
Contact us with your Reader Feedback
I was not expecting so many challenges, especially since I took over in 2019, in June. We started to work on a new strategy for the company, for the group, and then Covid came. That changed everything. We had to implement a lot of changes to the company and cope with the challenges. It was a good time, absolutely. Many positive things happened to the company, and we grew up with the business.
We reorganized our companies successfully, especially in China and in the U.S. I have had a great, supportive team ever since I started with the company for more than twenty years. I know all the people very well, and they cooperate and support me every day. It was a very good time for me, and I’m looking forward to another couple of years running the business.
Doug Glenn: Compared to 2020, will this year be a normal year?
Slawomir Wozniak: It looks like it. We still feel, however, the impact of the war in Ukraine and the supply chain deterioration caused by both COVID and the war in Europe. We also reorganized the way we do things in the company.
But you’re right, the business is good today. Although we see some recession on the horizon, this year is extremely good. It’s extremely good in the U.S. but also in Asia and Europe. Pretty much all the markets are growing.
New products were implemented on the market in the last couple of years, so we see a good future.
Doug Glenn: Tell us a little about the 60th anniversary coming up.
Slawomir Wozniak: There is an anniversary coming for RETECH. The company was established in 1963, so next year (2023) we would like to celebrate the 60th anniversary in Buffalo, NY. This is something which energizes the U.S. market.
We would also like to highlight our footprint on the U.S. market because we have three companies. We have RETECH, SECO/VACUUM Technologies, and SECO/WARWICK Corporation. We like to see the companies working together, and we see a big interest from U.S. customers to get equipment made in America. RETECH produces vacuumatological equipment (vacuum melting equipment) in the United States. We would also like to build vacuum furnaces in the U.S. SECO/WARWICK Corporation has been in business for many years, and we would like to continue with production of atmospheric furnaces and aluminum process furnaces. We are also thinking about aluminum brazing equipment we build in U.S.
Doug Glenn: I want to talk about SECO/WARWICK group and strategies. I know you manufacture equipment, but the emphasis has always been on technology.
What can our readers be looking forward to in terms of technology?
Slawomir Wozniak: We are a typical technology, an engineering company which provides technological solutions for our customers. We not only provide equipment, but we provide complete solutions for our customers.
What we see on the market is a deep interest in what we call “green technologies.” These are all the technologies that are in line with reducing the carbon footprint. Our technologies can provide solutions for our customers, like low pressure carburizing (LPC), zero-flow nitriding, and all the other technologies which also reduce the time for the process and energy consumption. We see a big boom because the carbon footprint needs to be reported by our customers.
Interest in "Green Technologies" Source: Unsplash.com/ShubhamDhage
We have to provide a report of what the carbon footprint generated during production of our equipment was. We also must provide a report of what the equipment would produce during a process. We have some solutions which significantly reduce the emission of carbon dioxide. This is what our customers are looking for.
We see a big interest in conversion of heating systems from gas to electric. Customers can buy green electrical energy, but they cannot buy the “green gas” right?
Doug Glenn: Not unless you do hydrogen which isn’t quite ready yet.
Slawomir Wozniak: Right. All these technologies are very much in the interest of our customers. So, this is why we are forcing also, the new development of our solutions to replace all technologies like gas carburizing by low pressure carburizing. This is what we see on the horizon.
Car manufacturers are declaring that by 2035 they will not be producing any more combustion engines in cars. We have a great product for brazing of battery coolers for electrical vehicles, an aluminum brazing process. This equipment is produced in Europe and in China, and we provide the solutions for global OEMs. Also, we see booming technology. With the growth of immobility we also see a growth of our business.
Doug Glenn: Have you seen much of the growth in the green movement? Have you seen it as much in North America as you’re seeing in other regions of the world?
Slawomir Wozniak: We see some interest from the customers. It is not as big as it is in Europe. With the global supply chain, even our U.S. customers, when they produce certain components, they also need to be in line with the global strategy. The end-user is the user of the components which are heat treated in our equipment. The end-user will ask for the certification of the carbon footprint. This is why it is still not on the level as we see in Europe, but we see more and more customers/companies asking for green solutions because they need to also be in line with the trend.
Doug Glenn: It seems the North American market tends to be a little slow on the uptake on these green things.
What light can you shed on the plans for SECO group in North America over the next five/ten years?
Slawomir Wozniak: This is the right time because we are working on the strategy now for the entire group, particularly for the U.S. market. We have three companies in the U.S., and we would like to build more equipment. This is in line with the interest of our customers.
[blocktext align="left"]There is a trend of reshoring and moving business back to North America, particularly to the U.S., but also to Mexico, to better serve the market and provide quicker solutions. We would like to build more equipment in the U.S. A lot of businesses are moving their production from southeast Asia (particularly from China) back to the U.S.[/blocktext]
We can provide the solutions to help our customers to run the day-to-day productions in a cost-effective way with these green technologies, but also with technologies which can reduce the cost of the production, the cost of heat treatment processes, and metallurgical processes. This is why we would like to build more equipment here.
RETECH, our company which provides metallurgical vacuumatology solutions, is very busy with the new locations. We have a lot of projects which are fully made in the U.S. We are now analyzing how to cope with the challenge of the U.S. market to build vacuum furnaces in the U.S.
Today, we only import vacuum furnaces from Poland. In Europe, in general, the lead time of some components is growing. Energy and labor costs are also growing, so we’d like to build vacuum furnaces also in the U.S. to better serve our customers. This would be the main focus for the next few years — to reinforce our operation processes here in the U.S. and also to organize how to serve the U.S. market by local manufacturing.
Doug Glenn: I think it would be helpful to delineate the three companies that you’re talking about, the North American companies.
Slawomir Wozniak: RETECH. We moved from California to Buffalo, NY, roughly three years ago. We have a nice facility. We are quite busy there with production and assembly of vacuumatological equipment.
Doug Glenn: Which is, basically, vacuum melting equipment.
Slawomir Wozniak: Right. Things like plasma equipment, electron beam equipment. We would like to even look for more space because we have so many projects. We still have our office in California, because we still have some good employees who contribute to the performance of the company. We would like to maintain this office in California.
With SECO/VACUUM Technologies, LLC, we would like to start building equipment for the North American market. We have a new setup, a new office, and a new facility with some floorspace where we can assemble the furnaces. We would like to start from assembly and eventually, double up the processes and completely build the equipment here in the U.S.
SECO/WARWICK Corporation — we just hired a new managing director in June of this year, Marcus Lord. His main focus is to grow our business in the U.S. particularly for our aluminum process equipment and also for thermal equipment.
Our goal is to build equipment in the U.S., maybe not in-house fabrication, but use our subcontractors, and then to do the assembly in the facility. We are also looking forward to set up a facility in the U.S.
Doug Glenn: RETECH has moved manufacturing to Buffalo, NY. SECO/VACUUM Technologies is still located in Meadville, Pennsylvania, but not in the previous building. They do have some manufacturing capabilities, although there is not really any manufacturing going on there except for spare parts, I assume.
Slawomir Wozniak: Spare parts and retrofits.
Doug Glenn: The last company was SECO/WARWICK Corporation, which is big in aluminum and general line thermal equipment.
Slawomir Wozniak: We would like to continue with this business and build equipment in the U.S.
Sławomir Woźniak and Doug Glenn Source: Heat TreatToday
Doug Glenn: That gives us a sense of the direction over the next five years or so.
Poland (your headquarters’ location) has been in the news quite a bit because of the war between Russia and Ukraine. How has that impacted your company and maybe individuals in your company. Has it impacted your ability to manufacture in Poland?
Slawomir Wozniak: It was a big shock for everyone at the end of February of 2022 when the invasion of Russia happened to Ukraine. For our company, the main heat was linked with the supply chain of some materials, especially commodities like steel, which were supplied for many, many years from either Ukraine or Russia.
Then, the prices of energy, like gas and electricity, also increased significantly. We also had some businesses in Russia; we have a SECO/WARWICK company in Russia to provide services and sales, but we stopped, pretty much, all activities there. We have just completed all the contracts, and we are not promoting our equipment there. We are not providing any quotes to Russian customers; we stopped our activities there.
It was not a big impact on our business because the volume of the business in Russia was not so big.
However, since the war started, we have realized that a lot of customers linked Poland with Ukraine as a country which is very close and, anytime, can be in the conflict.
So, many customers were worried about the situation, and they started to ask us, “Is our project safe? Can you still deliver our project?” So, we had to guarantee and confirm, “Okay, everything is fine. We can run the projects.”
There was a time, especially in the second quarter, when the delivery time of some materials were extended because of the situation. It has improved, and today we do not see much impact on it. Obviously, from the job market perspective, it was also significant, in part, because many migrants moved from Ukraine to Poland.
Doug Glenn: I think Poland was the number one country to receive immigrants.
Slawomir Wozniak: Exactly. We organized a lot of support, as a company and as individuals, with private activity to support the Ukrainian immigrants.
From our side, we have seen some shock and some impact on our from the other side. A lot of companies also started to think differently. For them, it was the first shock three years ago that impacted the global supply chain — many, many materials and then goods. This war was a second wave of impact on the businesses. We see that some companies decided to move their businesses to change their supply chain and, I can say, we even benefited from that because we see some growing business because of the situation.
In the end, I would not say the war is a good thing, obviously, but it is also positive thing for businesses.
We also have some solutions for the defense industry. We see growing interest — not only in Europe, but globally — in investment in capital equipment for increasing the production of some defense equipment.
Doug Glenn: Over your first four years in office, as the CEO, you’ve had to deal with the pandemic and you’ve had the war breaking out. I know there are some other issues, such as labor shortages and supply chain issues.
What is keeping you up at night worrying? As you’re looking forward, what are the things you’re concerned about?
Slawomir Wozniak: One, you just mentioned, about the labor market. We know that the demographic factors are very, very bad for many, many countries, including China. Today, it’s okay, but if you look long-term, the demographic doesn’t look good. We are focusing, now, on how to replace the human factor by automation, how to simplify the processes, how to implement the solutions which don’t require a lot of labor. So, automation is one thing and simplification of some processes, standardization of some solutions. We’ve focused on vacuum equipment especially. How can we reduce the manpower required to build the furnaces?
The second area is definitely the geopolitical situation, especially the tensions on the line between the U.S. and China. We have a lot of businesses in China, today. We also export from China, and to other countries. This is something which we have to look very carefully at how to recoup and handle if there were escalation from sanctions or limitations on the business and possibly to export our equipment.
[blockquote author="" style="1"]This is why we would like to focus more, in coming years, on the Indian market. We would like to set up production capacity in India to produce more equipment. Then, particularly how we can serve the Indian market which is growing. We see a lot of potential in India, but also later to use our capacity there to export some equipment to serve other markets. This is our focus for the next few years.[/blockquote]
I think the geopolitical situation is the thing which is out of our control, for everybody. Even the job market, as I said, we can cope some. How? We can attract our employees, and we can attract potential employees to join our company. With the geopolitical situation, we can do nothing.
Doug Glenn: We’re at the mercy of the leaders, which is always a scary thing.
You’ve talked a lot about green technologies. Is it safe for us to say that SECO is still in the business of the more conventional gas-fired type equipment around the globe? Or are you moving away from that?
Slawomir Wozniak: We do less and less gas-fired equipment. Gas-fired equipment was, in general, an atmospheric type of equipment. We changed the strategy for this product line. We have just narrowed our portfolio to a few types of equipment only. For some solutions, obviously, we still offer gas-fired heating systems, but we see more and more interest in using electrical heating systems. There are some developmental projects to use the combination of hydrogen and natural gas. This is the direction which we see from supplies of heating systems partners, and our customers are looking to get solutions which we call “the green solutions.”
I would say that, in the long term, we will not provide combustion systems in the equipment, but, currently, we still have them in our portfolio. I don’t really see that this will maintain for a long time, especially, as I said, since we changed our strategy for general products and for thermal product line. We do not use many of the solutions for combustion processes.
Doug Glenn: Here in the U.S., you are going to transition many non-vacuum lines from gas to electric?
Slawomir Wozniak: Yes. But, for some solutions, you cannot. We must have combustion and we obviously offer melting equipment and also some processing products. But we are very flexible and we can offer various solutions for our customers. We always try to adjust our proposal to the customer specifications and customer expectations.
Doug Glenn: It is probably safe to say that, within the next 5–10 years, you’re still going to be doing some combustion-related stuff, especially in North America. It’s going to be demanded. As most of the rest of the world knows, we’ve got relatively cheap energy.
Slawomir Wozniak: Less definitely than Europe, especially with the current situation with the supply of natural gas.
Alan Gladish (r), Praxis Communications, Inc., and Katarzyna Sawka(c), Vice President Marketing at SECO/WARWICK, were present at the interview with Doug Glenn(l). Source: SECO/WARWICK
Doug Glenn: Alright, last question: You’re obviously enjoying your work. You enjoy your team. The company is doing well. What excites you, personally, about the next 2, 3, 4 years at SECO/WARWICK?
Slawomir Wozniak: As I said, I have a great team which supports me every day in all of the challenges that we are facing, like every company. I love my job. I’ve bonded with the company. I grew up with the company. I would like to see the company develop and grow with new technologies, with market requests and new solutions.
We have great R&D teams — one in U.S., one in Poland — and we work on new solutions. I see that we can change a lot of industries with our solutions. This keeps me really energized every day, to discuss new technologies, new solutions, and how we can impact the development of various industries like aerospace, the energy sector, and the automotive industry. I’m proud to see some cars with our components.
Doug Glenn: It keeps you energized!
It’s good to enjoy your work, and it’s good to have passion for the future. I think that trickles down to your organization; you certainly have.
About the expert: Slawomir Wozniak started his professional career at SECO/WARWICK in 1994 initially as a service engineer and then as a deputy manager of CAB. Later he was posted to SECO/WARWICK Retech in China before an appointment of managing director at SECO/WARWICK Allied in India and chief operating officer of SECO/WARWICK Group. Later he was appointed managing director (Asia) and member of the management board at SECO/WARWICK SA. In 2018 he became vice president of the SECO/WARWICK SA Management Board, chief operating officer of the SECO/WARWICK Group, and he is the current president of the SECO/WARWICK Group.
What does cybersecurity look like in a heat treat shop? In this episode, Doug Glenn, publisher of Heat TreatToday and host of Heat TreatRadio, will be speaking with four industry experts about this challenge: Heather Falcone, CEO of Thermal-Vac Technology, Inc.; Brian Flynn, plant manager at Erie Steel Ltd.; Mike Löpke, head of software & digitalization at Nitrex Metal; and Don Marteeny, VP of Engineering at SECO/VACUUM Technologies LLC. Watch, listen, and learn all about the risks, preventions, practical steps, and future outlook that this panel has to share.
Below, you can watch the video, listen to the podcast by clicking on the audio play button, or read an edited transcript.
The following transcript has been edited for your reading enjoyment.
Doug Glenn (DG): Welcome to another episode of Heat Treat Radio. We’re going to talk about a relatively serious issue today. I hope to have a little bit of enjoyable time doing it. I’m really happy to have these four people on the call with us. We’re going to talk about cybersecurity -- probably one of the most pressing issues. Obviously, it’s not heat treat specific, but we’re hoping to take some of the specific issues that deal with cybersecurity and, if possible, drill them down into the heat treat industry, as best we can.
So, I’d like to introduce our prestigious crowd here today. They’re going to talk a little bit about it.
Contact us with your Reader Feedback
Heather Falcone CEO Thermal-Vac Technology, Inc.
First, I’d like to introduce Heather Falcone who is the CEO of Thermal-Vac Technology, Inc. out of California. Heather is the CEO, as I mentioned, and currently serves as a member on the board of directors of the Metal Treating Institute. She is a recognized trainer, writer, public speaker on a variety of topics such as leadership, business, and heat treat equipment. At her company, she has led them to be fully compliant in missed 800-171 and DFAR 252.204-7012 -- that’s important, I’m sure -- cybersecurity program as well as EOS system. Heather is, in fact, a member of Heat TreatToday's 40 Under 40 Class of 2019. And I, also -- I don’t know if they’re going to be able to see this; I’ll put it up on the screen if not -- there’s Heather’s picture in a really nice magazine that we got about leadership. Anyway, I am glad to have you here, Heather.
Brian Flynn plant manager Erie Steel Ltd.
Next is Brian Flynn from Erie Steel, Ltd. Brian is a third-generation heat treater. He attended the University of Cincinnati earning a Bachelor of Science and Chemical Engineering degree with a minor in Material Science. He’s also completed an executive MBA from the University of Toledo. As a plant manager, he has close familiarity with technology development, people skills, customer service, and management of technical services. He is also a member of Heat TreatToday's 40 Under 40 Class of 2021. We’ve asked Brian to get involved here because I think he’s probably got a good perspective on implementing some of this cybersecurity stuff. I appreciate you being here, Brian, thank you.
Mike Löpke head of software and digitalization Nitrex Metal
Next on our list we have an international entry -- Mike Löpke from Nitrex, actually. He’s working out of Germany, right now, but let me read what we’ve got here. Mike has been with Nitrex going on two years and is leading the creation, implementation and marketing of new digital platform for the Nitrex group. He has a background in mathematics and physics as well as substantial knowledge in R&D and metallurgical modeling and is currently in charge of Nitrex software and digitalization department. His expertise in AI (artificial intelligence) and process prediction led Nitrex to develop the very first IIoT-based platform called QMULUS. His thirst for knowledge enables him to remain ahead of evolving technologies. As I mentioned, he’s working out of Germany and he was, and maybe still is, a professional wind surfer. I did enjoy the videos, by the way, Mike. It was very, very good.
Mike Löpke (ML): Thank you very much!
DG: It’s interesting and it looks exciting. You certainly went to some nice places there.
Don Marteeny VP of Engineering SECO/VACUUM Technologies LLC
Finally, I would like to introduce Don Marteeny (DM) who I’ve had the pleasure of working with in the past. Don, it’s always good to see you. Don is the VP of engineering at SECO/VACUUM Technologies for over 5 years. During his career, Don has fulfilled many roles including 3 years as a project engineer, 2 years project manager and 2 years as the engineering team leader. He’s a licensed professional engineer. Don led the implementation of a 3-D modeling tool at SECO/WARWICK, when he is not busy being a Cub Scout den leader, which is great, Don presents papers on state-of-the-art heat-treating technologies. Don is also a Heat TreatToday's 40 Under 40 Class of 2021 recipient; congratulations on that. And Don’s just a heck of a nice guy all around, which I’m sure all of you are!
It's good to have you all.
Let’s jump in, guys. This is a relatively serious topic that we’ve got going on here but let me just throw out some questions to you. Heather, maybe I’ll start with you, if you don’t mind.
When we look at the risk potential in the heat treat market, I guess the first question that comes to my mind is: Okay, who should really be worried about this? Who are some of the people? Brian, maybe I’ll jump to you after Heather is done with some input on that, as well. Go ahead, Heather.
Heather Falcone (HF): Well, the short answer is literally everybody. Literally every person in the United States is subject to being a target for a nation-state level adversary such as China, Russia, Iran, North Korea. No one is safe, no one should assume they are safe, and every single person in this country, regardless of whether you’re a businessperson or not, should protect the data that keeps us safe.
DG: Do we have a sense, Brian, maybe over to you on this -- and again, as I mentioned before we started, if somebody doesn’t have a comment on this, just pass on it -- but are there people or organizations or systems in the heat treat industry, specifically, that are at a higher risk? What do you think as far as risk?
Brian Flynn (BF): In terms of age group demographics the Baby Boomers as well as Gen Z and younger are considered the most vulnerable for cyberattacks. Baby Boomers didn’t have great exposure to today’s brand of cyberattacks nor did they grow up with the internet and computers as we know them today. Gen Z and younger, there is a certain carelessness in terms of sharing personal information they’re too trusting. On top of that, Covid created new types of uncertainty in conjunction with the influx of new users going online since 2020.
But more from a business perspective, I guess it depends. Healthcare, government and financial-like institutions pose the highest potential reward but also the highest risk. In terms of frequencies, small businesses, like myself as a commercial heat treater, are the number one target as they typically lack resources and capital expenditures in order to invest in the infrastructure. And it might just be a pipeline where they’re going through the small businesses to get to my bigger Fortune 500 customers, but it’s really mainly phishing emails that are infected with malware. Over the past 12-18 months, it’s been crazy how many have made it through our firewall.
DG: Over to our equipment guys. I should mention -- Heather and Brian are both commercial heat treaters, Mike and Don are really both kind of equipment guys, although Nitrex also does some commercial heat treating, as well. Don, why don’t we start with you. The same question: Who’s at risk here? And then, Mike, we’ll end with you, please.
Don Marteeny (DM): Well, in addition to what Brian said, which I found interesting on some of the demographics, it’s important to realize, too, that it’s not just people, it’s also equipment. The equipment is becoming more and more interconnected, especially with the IIoT capabilities that most of them have now and all the unique features that that brings, but what that means is -- in order for that technology to function as it intended, it has to be connected to the internet which opens up more doors for access to sensitive data. And it’s not just data that you receive, it’s data that you generate, right? And that’s the important thing, I think, that everybody’s got to realize is that once you’re in that chain of subcontracts, shall we say, and you’re working with those folks that are contracting to the government -- handling sensitive data, you’re in that, too. It’s important to recognize that it’s not just you and your users but also your equipment and how it’s interconnected to the network.
DG: I’m reading a book right now -- I’ll give a plug to this guy -- Mark Mills, who we’ve interviewed before, on this show actually -- it’s called The Cloud Revolution and he’s been talking a little bit about this. The amount of data that is out there, because we’re able to get data off of machines and things like that now and are doing more and more, is just skyrocketing. It’s that data that’s going to be an issue.
Mike, over to you; I just want to wrap up as far as risk assessment, here. Who are the people, organizations, equipment or whatever that is most at risk?
ML: From our perspective, there’s not that much to add. We covered already the topic so we have this human factor which plays a really, really big role in terms of cybersecurity, how people are really sloppy and do not have the right mindset to treat data as they should. We have also, a lot of times, not the right policy in place, we do not have the education needed and so on. There is always this human factor.
But also, with heat treatment as a really old industry and steel manufacturing, as well, we have a lot of facilities with outdated infrastructure. This is also a also big topic. Outdated infrastructure, old, dated network designs firmware which we do not need to talk about it’s 20 years old and older so nobody knew about the potential risks that arise during the last decade and during the last years. This is also a really important factor. That’s it, from my perspective. Everyone, as said, is at a high risk, so, summing it up -- it’s literally everyone and everywhere.
DG: If you think you’re safe, you’re not, right? I think when Heather first started talking, I thought, “Boy, this is going to be a horror show.” If you think you’re safe, you’re not; you’re most at risk.
Let’s talk about data and data storage. Those types of things are really at the core of this, I think. Where are we going to store of all our data? How do we do it safely? When it comes to data storage, what problems have you witnessed or are you aware of, and how about solutions for data storage?
Don let’s start with you on this one then we’ll go to Mike. I know a lot of companies say, “Well, I just want to keep my data in-house.” Is that the answer? What are we doing with data?
DM: That varies. From my observations, it varies from customer to customer, industry to industry. There is a sense to move it to the Cloud, just because it’s easier to manage there, but with that brings risks. I think everybody’s got to be aware of that when they make that decision. On one hand, do I maintain my own servers, do I hire the people to man those servers, etc., or do I pay somebody else to do that in the Cloud? Do I take that risk of the data being someplace I don’t know and I rely on the Fortune 500 company who I’m contracting to maintain the Cloud to secure it, or do I do it myself? Especially for small businesses, these are not easy questions to answer. Like I say, I’ve seen both. And, again, with the invent of Industry 4.0 and IIoT, the pressure to move to the Cloud is pretty high, so, if you want to take advantage of those technologies.
DG: Mike, how about you? What do you think as far as data storage and things of that sort?
ML: I think Don mentioned already the two options we have. We could take of all the data storages ourselves, having big data service on premises, having people responsible for it, managing everything, keeping it running, no creation of redundancy, call it like this, having back-up systems -- all of these things you would need to manage by yourself. And the requirements are getting tougher. If you think of having data for the aerospace stored, you’re talking about decades of years, so that’s it.
The alternative is to put everything to the Cloud so then you’d just say, “Ok, I need more data” and more data storage space is available. You can also make use of all the security measures created, for example, by the big Cloud infrastructure providers like AWS in Asia. They are professionals in this. If they say your data is secure because we are using the latest technologies, I think you can be sure that it is. We, at Nitrex, rely fully on this. We say we could not do it better. There are thousands of people working every day on Cloud security, on infrastructure security, and so on and so on. I think our facilities could not be safer.
DG: Brian, let’s go to you on this one and then, last, to Heather. Data security -- if you want to make comments on that and maybe even, if I can put a little sharper point on the pencil on this -- just because a person keeps data in-house, does that make them safe from cyberattacks? General question, or if you want to answer that specific one, Brian.
BF: In today’s climate, the security of the data storage remains at the top of our lists. Knock on wood, very fortunately, we haven’t been on the receiving end of any of those types of cyberattacks, likely because we have a good firewall in place. More relevant to Erie Steel, the problems we face are data storage limits, length of data retention and scalability, and also accessibility -- whether it be video records, furnace records, quality records, shipping records, the list goes on, as far as how long do we want to retain that data and how accessible does it need to be? We utilize surveillance cameras, not spying on employees but really more proof of key operations, proof of start, proof of completion. The cardinal sin of heat-treating is don’t ship a green part back to the customer, so what better way to prove that other than by surveillance systems.
But that poses an issue -- we make sensitive cameras, increase the sensitivity, length of retention goes down. It’s a nice balance between form and function as well as retention, whether we use IP high-definition cameras or low-definition cameras. But that’s on its own internal server, on-site.
A lot of our continuous furnace trending software is continuously recorded -- that’s on its own separate dedicated server with off-site back-ups. Then we have all of our PLC data -- that could fill up a server in a matter of weeks if we really wanted it to. At times, we were recording every second; we don’t need to do that for most operations. Every minute, make the data accessible for a month and then, after that, we send it off to the Cloud.
For our ERP system and our quality management system, we utilize Bluestreak which is a web-based platform. We used to have on-site grid-based platform and that frees up a tremendous amount of space for the server so we can A. keep it 70% or less for capacity reasons. The only issue then, of course, is if we have a power outage, we lose internet -- but those are risks, at this point, that we’re willing to take.
DG: Heather, how about you? Data storage, generally speaking, what’s the situation?
HF: I think whether you’re deciding to store locally or in the Cloud, there are a couple things to consider: your digital rights management and your data loss prevention. If you’re working in-house, that means isolating assets on the land to make sure that, if there is an infection, it stops immediately. That’s one of the basic controls in, what is now, level 1. You have to have some of that in place so that if someone does get into your system, and we’re not talking a brute force attacker, we’re talking a person with the password of 1 2 3 4. We’re talking about the person that has not changed their password in 23 years and they’re still working on a DOS-based system. All those legacy systems that are not yet updated, that’s where the real risk comes from -- storing data locally. It’s really user behavior oriented that’s backed up by the solid digital rights management and data loss protection, as far as storing locally. One thing to be very careful about when moving to Cloud solutions, most commercially off the shelf available Cloud solutions are not compliant within the 800-171. If you’re talking about just Office 365, you have to move to the government version. Now we’re on zoom.gov instead of regular zoom, Doug, I don’t know.
DG: We are not, so be careful what you say.
HF: The problem with that is when you move to those Cloud solutions, they are inherently user prohibitive. They’re awful to work with, and they’re extremely expensive. You are kind of in a rock and a hard place: do we store locally and take on more risk and more in-house compliance cost or do we trust these big guys who have a billion-dollar backing them up who seems to know what he’s doing but also humans are humans and it’s still an inherent broken system? We all have to be careful and take our ownership of the programs that we’re putting in place -- that we have working knowledge where our data is going, how it’s being backed up, how it’s being stored or retained.
DG: Just a quick round-robin question, just kind of a yes or a no, and if you want to elaborate a little bit, feel free: Do you think, in today’s day and age, that it’s just as safe to store things in the Cloud as it is locally? Mike, what do you think?
ML: Yes. But you have to respect the requirements.
DG: Don, what do you think?
DM: Yes, for the most part. Like we said, the larger companies have teams of people working on this every day, so not only can they react, they can be more proactive in staying out in front of it than the rest of us can because they the resources. So, in theory, yes.
DG: Heather, what do you think? Just as safe to store in the Cloud as local?
HF: I believe that it has the potential to be more safe because you can rely on a group of resources that you don’t have to actively manage yourself. However, it takes a lot of oversight and research. It might be easier for a smaller company to create a very small locus of control as opposed to moving to a large collect Cloud solution during their migration to CMMC.
DG: Brian, how about you? Just as safe?
BF: I think the short answer is yes but, you know, it depends on which Cloud are we talking about and what does your internal infrastructure look like as well as what are your internal policies. Then it gets into more of a convenience discussion. How do you need that data? How frequent do you access it? But, I think, there’s the potential to be as safe or potentially more safe.
DG: I want to take a brief break and ask Heather a question. If you can just do a 30-second/60-second explanation of CMMC for us, and then we want to ask some questions about that. But I want to make sure that those who are listening who might not know what that is -- what is that? CMMC -- it’s important.
HF: It’s the Cybersecurity Maturity Model Certification. The government, in all of their perpetual wisdom, decided that they’re really tired of getting attacked by all the bad guys. To protect the state of the defense infrastructure and, I guess, maybe protect themselves because they have to do it too, they designed this system. Now, for today’s talk, I want to make sure that we understand that I’m personally going to be vacillating between CMMC 1.0 and CMMC 2.0. They are drastically different -- CMMC 2.0 is in rulemaking, but it’s got a lot of exciting, better things, potentially, in it versus CMMC 1.0. The point is, CMMC 1.0 is the law of the land and has been since 2019, so, it’s up to everyone who deals with the federal government to ensure that they are up to the minimum standard requirements for CMMC 1.0 which is just, basically, a self-assessment and some basic controls.
The government really wants to put in place the supply chain that is not full of holes for the enemy to take our most trusted and effective data.
DG: I’m curious, when it comes to CMMC then, implementation, best strategies for implementation, how do we find out about it more? Heather, I’ll stick with you on this one and then maybe we’ll move down to Mike and Don and then over to Brian.
CMMC -- what are some good strategies for implementing this?
HF: The first thing is to identify what you’re going to attack. If your whole company does not deal with CUI or FCI (control of unclassified information or federal contract information), then you don’t need to be talking about CMMC. The first step is to get your senior leadership team together and start with a block of information that’s manageable, either by location, by area, by contract, by project. Start at that top level and read the flow-downs to find out if you even have to do this, then decide a plan of action. I strongly recommend a phased integration approach over a period of about 18 months. If you’re trying to jam this into a 6-month process, it likely will be unsuccessful, strictly because that’s not enough time to even get the written policies and procedures in place. Plan for this to take about 18 months to 2 years and plan for it to cost you about $180,000; it’s about 60 grand a year. This is what the government, the Department of Defense says it will cost.
"The first thing is to identify what you’re going to attack. If your whole company does not deal with CUI or FCI (control of unclassified information or federal contract information), then you don’t need to be talking about CMMC. The first step is to get your senior leadership team together and start with a block of information that’s manageable, either by location, by area, by contract, by project. Start at that top level and read the flow-downs to find out if you even have to do this, then decide a plan of action." - Heather Falcone, Thermal-Vac Technology, Inc.
DG: Alright. You’re speaking from experience though, yes? You guys have done this?
HF: Absolutely, yes. It took us closer to 2 ½ years but, luckily, we started early enough to where that phased approach was okay.
DG: Mike, how about to you -- CMMC. Are some of your customers needing to do it? Are you guys needing to do it? What do you think?
ML: Nitrex is a solution provider so we are not only having commercial heat treatment, but we are also creating furnaces, we are building furnaces. We are also creating this control software and lately we released our QMULUS IIoT platform. We are really involved with this topic because we need to make sure that our customers are getting a solution which is CMMC compliant in the end. One thing which I really would like to mention here is that it does not only stop with the software. It’s not only software, it’s also controllers, it’s a hardware on the controllers, it’s even the network. Let’s say, a component on your controller which has to be CMMC compliant, in the end, which makes it really hard for small companies to take care of it. I suggest that you outsource a lot of these things. You can make your suppliers responsible for it, for sure. This would come with rising prices and so on, but for small heat treatment shops, it’s not maintainable, I guess. Maybe with the new approach of the CMMC release, which is relaxing a lot of things, it might be better, but we still do not know.
DG: Your suggestion is to outsource a lot of these, whether it be components or whatever.
ML: I would just like to add -- because we spend a lot of time to figure out what it really means (the CMMC things) and, as Heather already said, it will take you months to understand everything and if you’re not a professional in cybersecurity and maybe created these policies, you are lost.
DG: Don, how about you?
DM: I think I would echo a lot of what Mike is saying. As the whole industry goes more towards the IIoT implementing things, CMMC will be more and more difficult and you need help. Bottom line, unless you’ve got enough resources internally that can address the needs and understand, first off, as Heather mentioned, understanding the law (the regulations), in and of itself is usually enough to keep someone occupied for quite some time. But, even after that, then knowing what it means in implementing it, getting the right person on it, would certainly help the process.
DG: Brian?
BF: I think Heather really hit the nail on the head. The first step is to make sure it matches your strategic plan and your business plan. Currently, this is not a certification that Erie Steel possesses. It’s on our business plan as a threat under SWAT analysis but based on our current and forecasted customer base, this isn’t something that we plan on moving forward on here in the near future.
DG: Heather, you had mentioned about the control of unclassified information. Can you just expound on that a little bit? If I remember what you were saying, you were saying that it’s important to know whether you’re in that category, right? Because if you are, you need to do certain things; if you’re not, you don’t need to do certain things.
HF: Yes, if you handle CUI at your company or if you create CUI, then you’re likely going to be subject to the DFAR’s requirements when they’re flowed down to you. If you’re a federal contractor, it’s likely you don’t have a choice in this; it’s going to be in your contract flow-downs.
If you want to know more about control of unclassified information, there is an ongoing and everchanging list that’s available to you on the National Archives’ website which is archives.gov. If you go in there and you search controlled, unclassified information, it has a subsection list by industry. If all you do is firearms, cool, click on firearms and it’s going to tell you which CUI you have. If you only work defense, ok cool, here’s a nice little chart. It’s an invaluable resource on picking out key terms of your parts of your business to see if it matches up with the CUI.
But also, FCI, which is the Federal Contract Information, grand jury data is protected. Now, do we all deal with that? No. But financial transactions and general data information that you might not think is protected is protected. Spend some time in the National Archives -- it’s not boring, I promise, it’s actually pretty easy reading. It has nice charts and hyperlinks.
DG: It sounds boring, if I may just say so. Being the National Archives doesn’t sound like a place I want to spend my Friday afternoon.
HF: Well, call me, I’ll make it more exciting for you.
"Lately, we started with education because, we said it already multiple times in this discussion here, that the human factor is the most important part. We need to sensitize people about all the risks and all the things the internet brings. That’s why we started to have these security trainings, web-based and so on, which really help, also, to make people aware of these things."
DG: I want to deviate a little bit from the questions that we sent and maybe wrap up with two questions. We’ll deal with them individually but I’ll get you thinking about it just a little bit. Because we want to make this fairly practical for people, question one will be: Can you tell us what your company has done, thus far, to address cybersecurity? Again, it’s going to be a range of things; some have done a lot, some have done a little. Then, the second question I want to ask you which we will wrap up with is: If you could put on your prognostication hat here and you’re looking into the future -- what do you see being some of the major movements that we’re going to have to be dealing with as far as cybersecurity? It’s a little bit of fun looking into the future and seeing what we’re going to have to deal with in the heat treat industry.
Mike, if you don’t mind, we’ll start with you with Nitrex. What have you had to do so far to really deal with the whole cybersecurity threat?
ML: In the past, we started with the human factor. Until 6 years before, everyone had administrator rights on his local PC and everyone was installing everything -- malware, spyware and even things which were ‘unsuspicious.’ But a lot of things happen in the background without even noticing and these actions are opening doors for cybersecurity things. That’s why we installed something like MS LAPS which is a local admin password solution so that we can make really sure that people are only installing things which have been approved and so on. This was one of the things. Then, we also introduced something like MS Defender as an antivirus solution which is hosted in the Cloud which is making use of AI-identifying things before they get really serious. This for all internal IT infrastructure, making use of the latest approaches and software solutions we can get.
Lately, we started with education because, we said it already multiple times in this discussion here, that the human factor is the most important part. We need to sensitize people about all the risks and all the things the internet brings. That’s why we started to have these security trainings, web-based and so on, which really help
In terms of our solutions which we are offering, we planned accordingly a roadmap on how to make it CMMC compliant. All our hardware, we have to rework our whole controller infrastructure which we are offering to make our furnace CMMC compliant. The same for our MES software which we are having on premise for QMULUS, as well, which is our IIoT solution which is hosted in AWS. Here, it really depends on our customers if you’re hosting it in the Cloud or in the usual, let’s say, public Cloud. That’s what we are doing. We’re investigating our needs and to the needs of our industry.
DG: Good. And we will get to what do you plan on doing in the future, too.
Brian, why don’t we jump up to you on this. So far, what is Erie Steel been up to?
BF: As I stated during the risk assessment portion of management review, cybersecurity is regularly listed as a consistent internal and external threat. Historically, it’s been less relevant than it is today so little action was done. Now, over the past few years, we’ve really focused in this area and targeted internally on internal infrastructure. With that, we always try to keep a focus on understanding current environmental trends in cybersecurity, but with anything, any policy, any initiative, it should start and end with a strategic plan. Plans need to be well thought out, employee expectations clearly communicated prior to rollout, and feedback welcomed throughout these transitions.
Here, we practice self-audits and realize that server capacity as well as the life expectancy of our server was a great concern. We met with IT several times and came up with the plan to replace and upgrade our existing server and came up with it in four separate phases -- phase 1 being clean up the current system, phase 2 being change the system over, phase 3 being the new file structure for day-to-day operations, and phase 4 is to implement our new cybersecurity policy. Right now, we’re approaching the end of phase 3; so we’ll be sitting down again and reviewing the cybersecurity policy. Like I said, though, if you have doubts, self-audit, or you can always have a third-party auditor come in and share their two cents.
Some other things we’ve done are antivirus, antispyware software -- those should be givens. When individuals need to access the servers remotely, make use of VPN’s, utilize firewall security, ensure management has a firm understanding on the server capacity and requirements, regularly back-up the critical data, have redundant back-ups in different locations, of course make sure your Wi-Fi is secure, passwords should regularly change, same for all the usernames. You’ll see this with a lot of larger companies -- you really want to limit access to data and limit authority to make changes.
One thing we have done is our PLCs are operating locally on our own internal internet in case there is a server storm, in case there is a power outage. Well, a power outage wouldn’t help us in that situation but in case there is a server storm or internet outage, we can still operate locally, we just don’t have all the trending software to support it like day-to-day operations.
DG: That, just by itself, sounds like a huge task. Just switching over a server sounds like a lot of work. I think a lot of companies are going to be listening to this, especially some of the smaller captive heat treaters. Where to start? I think self-audit is a good idea and good advice.
Don let’s go to you then we’ll finish up this question with Heather then we'll move into thinking about the future.
DM: From our perspective, we’re focusing on the human factor. We’re trying to increase training and then once it’s out there, we test it. Once in a while, you’ll get forewarned that sometime within the next 24 hours you’re going to get a phishing email and what do you do with it? Sometimes they won’t tell us and all of a sudden, it’s, “Oo, what’s that?” I’m not going to click on that link. But honestly, those are the doors that are easier to close that we need to.
Some other activities have been like adding multifactor authentication where it’s necessary. Yes, it takes longer, yes, it’s a pain, but it’s necessary to make sure it is you and not somebody else. And then, as everybody else has mentioned, the usual firewalls, protecting Wi-Fi data networks, etc.
I did want to touch a little bit more on the equipment side, for just a minute. In my experiences with customers, sometimes an easier way to deal with this, especially because the interconnectivity to the equipment is becoming more and more prevalent, it’s just basically have a separate service, a separate internet connection that you control. And it’s basically if you need help, if you need to connect that piece of equipment to the internet, you physically plug it in, if not, you take it out. And when it’s out, you are in control. On your network, you’re passing data where you need to and that’s it. It’s back under that umbrella. Then, when you physically plug it in, you’re doing so making that decision consciously to say, “Okay, for this period of time, I need it to be connected.” But at least, then, you have some direct control. Is it rudimentary? Yes. Is it maybe not the most convenient? Yes. But, until you’re to the point where you can research all the needed data and regulations, they can get you to the point where, at least, you have some control.
DG: Right. Nothing like a physical line to plug in and unplug to help you feel safe.
Heather, how about you? What has Thermal Technology been doing?
HF: We started with an assessment that we paid people to do -- an expert that came in and evaluated our system against the CMMC requirements. That was very scary and expensive and it felt like someone was speaking Greek to me and, frankly, I got bored within the first 30 minutes of him giving me the report. But that’s where you start. And don’t be afraid if you get a negative score on the darn test because you’ve got to pick a place and you’ve got to get the baseline.
The nice thing about CMMC is it’s progressive; it’s meant to be transitional. You’re not going straight to level 3 and your whole life is going to change. You go from that assessment and then you work your way into phase 1. The CMMC level 1 is meaning we’re doing this stuff; we just can’t repeat it and we don’t have any documentation. And then level 2 -- okay, now we’re doing stuff and now we’re going to make it repeatable by documenting it. Then phase 3 is now we’re going to make machines manage the processes that are documented so we can repeat them and do them. It builds upon itself. So, embrace the stages. That’s what we’ve done and we started all the way back when we were a .79.
DG: Out of what?
HF: Out of the level 1 – 3. We were .79. Now, I’ve seen people who are minus numbers (-2, etc.) and that’s okay. Everyone starts somewhere, and if you haven’t had to look at infrastructure as related to information technology in 20 years, then why would you have ever looked at it? Take it in the phased approach. That’s what we did and we baby-stepped our way in and took all the painful points and broke them down into 1,000 substeps and that was the best thing we could have done.
DG: We’re going to go backwards in order, if I can, and let’s talk about the future. I guess, what I want to get a sense from you guys, to wrap up, is 1.What do you see as being the greatest risks to your companies, and, I think, especially with our equipment guys with Nitrex and with Mike and Don, if you’re able to address from your customer’s perspective, 2.What are the issues with new equipment going in? What are the biggest risks that you’re seeing, if there are any, and what do you see us doing in the future differently than what we’re doing now as far as mitigating any of those risks?
Heather, back to you on this one?
HF: The biggest risk is complacency or denial. This will come to you and it already has. If you take the viewpoint of, “Well, I’ll do it when my customer makes me,” you will be so far behind the ball, it’s going to be painful. The absolute worst risk you could possibly take is not looking at it or denying that you’re involved in it. If you’re in heat treating, it is 90% likely that this is going to apply to you in some way. Now, the great news is CMMC 2.0 -- over 60% of the industrial supply base is only going have to be a level 1 -- that’s a self-report annually. That’s not that big a deal. Anybody can do that. And there are great resources that are being developed to help people that want to get that basic level of CMMC compliance.
So, don’t wait, don’t deny it, get your customers to pay for it, put it in your RFPs. It is an allowable cost for reimbursement; don’t let anyone tell you otherwise. If you need more help on that, let me know.
"On the note of chaos, when it sets in, communication is key. If you’re the responsible party, designate primary and secondary points of contact for cybersecurity support. Have performance incentives in place for the responsible managers. If you’re rolling out a new policy, based on the successful rollout of that policy, put some incentives in place. Maintain open lines of communication and welcome feedback."
DG: That’s one of the questions we didn’t get to and that was how to make your customers pay for it which sounds like a very intriguing question, but yes, you mentioned it there.
Don, how about you? We’ll go over to you on this one.
DM: I think, moving forward, a couple of things are happening: The labor market is changing; it’s changing to a demographic that’s more familiar with this technology, which is a good thing. Although, as we said, I think it was Brian that said earlier on, some of those generations may not be as sensitive as they need to be. But what that means is that the older days when we relied heavily on operators to know what’s going on, now we’re switching more towards the technology managing the equipment from the equipment’s point of view. What that means is there will be fewer people managing more equipment from fewer places. So, if you’re looking at a multilocation operation that’s managing data from a central location, that becomes pretty complex pretty quick; but it’s becoming more commonplace in the industry than it used to be. Obviously, that opens up a lot of doors for cybersecurity risk and that’s got to be carefully managed, in the light of CMMC and others as far as cybersecurity goes.
I think the future is -- the technology is there, it’s available, but it has to be implemented carefully and it has to be well thought out by people who know what they’re doing.
DG: Brian, I think we go to you and then we end with Mike.
BF: When chaos sets in, the one standing by your side, without flinching, can be considered your family. When chaos sets in manufacturing, managers must remain flexible, patient and understanding which leads to the difference between a leader and a manager. A good manager is not always a leader, and good leaders are always managers. Managers have people work for them while leaders have people follow them. On the note of chaos, when it sets in, communication is key. If you’re the responsible party, designate primary and secondary points of contact for cybersecurity support. Have performance incentives in place for the responsible managers. If you’re rolling out a new policy, based on the successful rollout of that policy, put some incentives in place. Maintain open lines of communication and welcome feedback. Make sure that training materials are available. Something that I’ve come to realize is that employees often shy away from asking for help. Instead, try to get the help at their fingertips and ask specific, strategic questions to prove they’re understanding.
Really, at the end of the day, conduct your risk assessments. You don’t know what you don’t know, and that’s 95% of what is knowledge today. Be cognizant of what’s out there. Let’s face it -- cyberwarfare, cyberterrorism are very real, very selective, quick and cheap attacks from the hacker’s perspective, and they remain anonymous.
DG: And devastating for the companies that are on the receiving end, potentially.
BF: On the microscale, it’s real, especially for small businesses.
DG: You’ve hit on an interesting thing, Brian, and obviously we can’t spend time talking about everything but, it’s just the way you address this from a personnel perspective inside your company -- are you having someone there that’s the point person for cybersecurity? This shows my ignorance, but that’s okay, it’s easy to do. Do they have a chief security officer, a CSO, now, I assume, adding to the ‘C-suite’?
But yes, I think that’s a good point.
Let’s go over to Mike. What do you see as being the future threats and how are we going to be mitigating them?
ML: I think there is not that much to add here. We talked about the human factor, as I said, is the most important thing. Education and also more of education is needed here. Also, with the people on the shop floor, they are often working still with pen and paper -- they are not really used to going with the digital mediums and components and so on. So, really, we have to be sensible there, as well. You mentioned that the management has to take care that they are not "steamrolled" by all these approaches. This is really important.
The other thing, I already mentioned as well, is to outsource as much as possible, if it’s possible. Talking about the hardware, the software components and solutions and so on -- if you can get a solution which is CMMC compliant and the vendor is stating it, get it, because it’s taking a lot of work from you.
DG: The last thing we’ll do, and you may or may not have anything for this -- any final thought you want to leave with the people that might be listening to this, watching this? These are basically going to be people who are manufacturers who have their own in-house heat treat shops, commercial heat treaters, suppliers to the industry. Are there any last comments that you want to leave?
Don, anything?
DM: The only thing I’d add is just to be proactive. That always helps in these cases. And what that means is up to you but be proactive to address it.
DG: I was thinking the same thing: Don’t stick your head in the sand. Or, if it is there, get it out. Get it out of wherever it is and pay attention. Be proactive.
Heather, how about you?
HF: That’s exactly right. And some of us have larger egos that prevent us from reaching out for help. Understand that the literal federal government wants to help you, and there are so many resources out there that can be a nightmare to navigate but start with the people on this call. Reach out, talk to someone, get outside your circle and start figuring out how to make it work for you.
DG: Mike, how about you and then we’ll end with Brian, if you have any other comments. Again, if you don’t, no problem.
ML: That statement of Heather’s, I think, of being proactive, ask for help, don’t be shy. Invest the money. It will be worth it to invest.
DG: Brian, how about you?
BF: I think, find what works best for your organization and remain flexible. Solutions to cybersecurity should not be a one size fits all approach, so plan for the worst and strive for the best.
DG: Guys, thanks very much. I appreciate it. This is a huge, huge topic. I know we’ve just skimmed across the top.